CRITICAL 9.9 GitHub

CVE-2025-53837

org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue

### Impact Any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The reason is that rendering output is included as content of HTML macros without further escaping and it is thus possible to close the HTML macro and inject script macros that are executed with programming rights. This can be demonstrated by adding

Affected Products

References

Published: 2026-09-18 · Source: GitHub · Feed updated: 2026-09-18
This critical severity vulnerability with a CVSS score of 9.9 was published on 2026-09-18 via GitHub. Affected: maven/org.xwiki.rendering:xwiki-rendering-xml < 14.10.2.

Risk Timeline

CVE Disclosed2026-09-18 · -1 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-11746Central Dogma: Hard-coded ZooKeeper replication secret 'ch4n63m3' with silent faCRITICAL
CVE-2026-73247Kestra: SSRF via Pebble http() function allows unauthenticated access to internaHIGH8.6
CVE-2026-11745Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshHIGH
CVE-2026-73245Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/envMEDIUM6.5
CVE-2026-11748Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentMEDIUM
vulnfeed aggregates 14509 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.